July 31, 2015 By Mark Wah 3 min read

The Data Breach Triangle

Too often, companies will invest in preventing the exploit through detection tools, identity and access management (IAM), vulnerability managers and so forth. But there’s not enough focus on core data security: encryption, data activity monitoring and data loss prevention, among other protection solutions. To have a balanced approach, you have to invest in all areas.

About Data Activity Monitoring and Data Loss Prevention

Let’s take a look at two complementary technologies: data activity monitoring (DAM) and data loss prevention (DLP).

DAM solutions should continuously monitor all data access operations in real time to detect unauthorized actions based on detailed contextual information — the who, what, where, when, and how of each data access. These solutions must be able to react immediately to prevent unauthorized access or suspicious activity by privileged insiders and potential hackers, plus automate data security governance controls in heterogeneous enterprises. With the right architecture, DAM can improve security and support compliance requirements through a set of core capabilities while also minimizing total cost of ownership.

Back in 2009 when DLP was the buzzword in the security industry, DAM and DLP shared the limelight. At the RSA Conference, main-stage talks were focused on DLP. Everyone thought it was the silver bullet for data security. But as time marched on, people realized it was a security pitfall – and that DLP alone was not sufficient enough. DAM and DLP needed to work together.

DAM and DLP certainly share some similarities: For example, both solutions focus on the data and its associated context, behavior and activity, in addition to content awareness. Both are well-suited in meeting compliance requirements like PCI, HIPAA and SOX.And both help with the involvement of line-of-business (LOB) owners.

But the offerings also have their differences. DLP is focused mostly on perimeter activities: the outbound network, endpoints, etc., while DAM focuses on the source of the organization’s crown jewels, usually in databases and data warehouses. DAM solutions have better visibility into the movement of sensitive data from the source to the next hop — applications, privileged users, spreadsheets, etc. DAM also includes the very granular context and behavior surrounding the data. Essentially, DLP concentrates on data at rest on database solutions, while DAM monitors data at rest, access and usage through SQL transactions, privileged users, etc., and even applies DLP concepts by blocking, masking or quarantining risky traffic.

A Porous Security Perimeter and Data Security

The modern-day perimeter has become extremely difficult to secure due to IT mega trends around cloud, mobile and big data, and first generation DLP capabilities simply have not kept up with some of the challenges. Businesses need a solution that includes current techniques and is able to integrate with DAM. It’s important to choose the DAM technology that can keep up with recent mega trends, work in real time and enable you to deploy with the least amount of overhead.

Learning about the most common data protection pitfalls can help organizations recognize their security weaknesses and improve their defenses. Watch the on-demand webinar “It’s 2 a.m.: Do You Know Who’s Accessing Your Sensitive Data?” to learn more about securing your critical assets and preventing data breaches with core data security.

More from Data Protection

Defense in depth: Layering your security coverage

2 min read - The more valuable a possession, the more steps you take to protect it. A home, for example, is protected by the lock systems on doors and windows, but the valuable or sensitive items that a criminal might steal are stored with even more security — in a locked filing cabinet or a safe. This provides layers of protection for the things you really don’t want a thief to get their hands on. You tailor each item’s protection accordingly, depending on…

What is data security posture management?

3 min read - Do you know where all your organization’s data resides across your hybrid cloud environment? Is it appropriately protected? How sure are you? 30%? 50%? It may not be enough. The Cost of a Data Breach Report 2023 revealed that 82% of breaches involved data in the cloud, and 39% of breached data was stored across multiple types of environments. If you have any doubt, your enterprise should consider acquiring a data security posture management (DSPM) solution. With the global average…

Cost of a data breach: The evolving role of law enforcement

4 min read - If someone broke into your company’s office to steal your valuable assets, your first step would be to contact law enforcement. But would your reaction be the same if someone broke into your company’s network and accessed your most valuable assets through a data breach? A decade ago, when smartphones were still relatively new and most people were still coming to understand the value of data both corporate-wide and personally, there was little incentive to report cyber crime. It was…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today